Skip to content
Security & governance

Auditable by design.

Governance isn’t a checkbox we bolt on — it’s wired into every answer, every record, and every charge, so you can prove what the AI did.

SOC 2 (in progress)
GDPR
EU data residency
No training on your data

Guardrails on every answer

PII redaction, jailbreak detection, topic control, and grounding checks run on every reply — always on, never optional.

Hash-chained audit log

Every action is recorded in a tamper-evident chain and independently verifiable.

/v1/audit/verify

Dispute any charge

Every verified resolution is inspectable and reversible — dispute any charge in one click.

How we protect your data

Security practices

Encryption in transit & at rest

Traffic is encrypted with TLS, and data is encrypted at rest. Secrets are encrypted and access-controlled.

Tenant isolation

Every workspace’s data is isolated at the database layer with row-level security and forced tenant scoping.

Scoped API keys & signed webhooks

Grant least-privilege access with scoped keys; verify every webhook with a signed, timestamped signature.

PII redaction & guardrails

PII is redacted and jailbreak/grounding checks run on every reply — always on, never optional.

EU data residency

Eligible customers can keep data in the EU. No customer content is used to train foundation models.

Hash-chained audit log

Every action is recorded in a tamper-evident chain you can verify independently via /v1/audit/verify.

SOC 2 is in progress. We’re happy to share our current posture and roadmap with design partners under NDA.

Security your team can actually verify.

Talk to us about compliance, residency, and the audit trail.

Supervised alpha · No credit card · You’ll never be billed for a handoff.